Description
An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of
attacker-controlled code. User interaction is required.
Published: 2026-09-11
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution via unverified driver upload
Action: Patch Immediately
AI Analysis

Impact

The vulnerability allows an attacker to obtain arbitrary code execution on a system running the Sentio Creator Device Manager extension by uploading a malicious device driver package. The driver bypasses normal verification controls, enabling attacker‑controlled code to run with the privileges of the local user. Because arbitrary code runs under the context of the process that loads the driver, the impact includes full compromise for the affected system.

Affected Systems

Affected products are SICK AG's Sentio Creator Extension 'Device Manager'. The issue is mitigated by upgrading to version 1.4.1 of the extension; no other version ranges are provided, so all earlier releases are considered vulnerable until the upgrade is applied.

Risk and Exploitability

The CVSS v3.1 score of 8.3 classifies the flaw as high severity. No EPSS score is available, and the vulnerability is not currently listed in the CISA KEV catalog, indicating no widespread exploitation is reported. Exploitation requires user interaction to supply the malicious driver package, so the attack vector is likely local or requires the attacker to persuade a user to load the driver. Given the high severity and potential for system compromise, the risk to environments that rely on the Device Manager is significant.

Generated by OpenCVE AI on September 11, 2026 at 09:20 UTC.

Remediation

Vendor Solution

Users are strongly recommended to upgrade the Device Manager extension for Sentio Creator to version 1.4.1.


OpenCVE Recommended Actions

  • Upgrade the Sentio Creator Device Manager extension to version 1.4.1.
  • If the upgrade cannot be applied immediately, disable or restrict the ability to upload custom driver packages, limiting installations to signed drivers only.
  • Monitor system logs for driver‑loading events and flag unexpected or unauthorized driver installations.

Generated by OpenCVE AI on September 11, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Sick Ag
Sick Ag sentio Creator Extension 'device Manager'
Vendors & Products Sick Ag
Sick Ag sentio Creator Extension 'device Manager'

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code. User interaction is required.
Title CVE-2026-80469
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Sick Ag Sentio Creator Extension 'device Manager'
cve-icon MITRE

Status: PUBLISHED

Assigner: SICK AG

Published:

Updated: 2026-09-11T14:06:15.667Z

Reserved: 2026-08-26T12:59:50.751Z

Link: CVE-2026-80469

cve-icon Vulnrichment

Updated: 2026-09-11T14:00:32.259Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T09:17:20.833

Modified: 2026-09-18T19:25:29.923

Link: CVE-2026-80469

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:56:32Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature